news.mlab.sh
Back to the feed
threat-intel

North Korean Hackers Deploy New Linux Espionage Toolkit

High
Summary

North Korean-aligned threat actors are deploying a sophisticated Linux espionage toolkit targeting automotive and media organizations in South Korea. The toolkit, incorporating a custom HAProxy plugin and various trojanized tools, allows for long-term surveillance, credential harvesting, and command execution, mimicking techniques previously used by APT37 and Lazarus. Initial access was gained through a Groupware login portal vulnerability, and the campaign is linked to Operation SyncHole.

North Korean-aligned threat actors are currently utilizing a new Linux espionage toolkit to conduct long-term surveillance operations against organizations in South Korea, specifically within the automotive and media sectors, according to Rapid7. The toolkit is a complex system built around a custom HAProxy plugin named ‘ted backdoor’ and trojanized versions of tools like ‘agetty’, ‘atd’, ‘crond’, ‘polkitd’, and ‘sshd’.

This framework is deeply integrated into the victim’s infrastructure, with the ‘ted backdoor’ compiled as part of HAProxy version 2.8.12. It leverages the HAProxy’s native API – including its internal memory pools, event scheduler, and process management – to intercept and inject HTTP traffic, execute commands, and maintain persistence, all while appearing to function as a standard load balancer.

Initial access was obtained through the exploitation of a Groupware login portal vulnerability. The SSH keylogger, acting as a staging server, was used to harvest credentials, facilitating lateral movement within the compromised network. The toolkit employs a curl-based RAT (CurlRAT) that polls a Command and Control (C&C) server every 12 hours, executing commands stored in its configuration, decoding and writing new configuration payloads, and deploying a full interactive PTY shell.

The ‘ted backdoor’ establishes C&C communication for data exfiltration, script injection, and command execution, while the balancer redirects or serves malicious content to selected users browsing through it. Attack artifacts and infrastructure suggest a connection to watering hole techniques previously used by APT37 and Lazarus, and the campaign’s timeline overlaps with Operation SyncHole, attributed to Lazarus last year.

The threat actors utilized low-cost commodity top-level domains (TLDs) and blended payload delivery traffic into normal web browsing, mimicking Naver’s pstatic.net domain to evade detection. The toolkit is designed to persist during long-term espionage, capable of stealing cookie sessions, credentials, redirecting users, conducting drive-by download attacks, and hiding tampered pages to specific IP ranges.

Read the full article at SecurityWeek